This update for python311 fixes the following issues:
* Updated to Python 3.11.15
* CVE-2025-6075: If the value passed to os.path.expandvars() is user-
controlled a performance degradation is possible when expanding environment
variables (bsc#1252974).
* CVE-2025-11468: header injection when folding a long comment in an email
header containing exclusively unfoldable characters (bsc#1257029).
* CVE-2025-12084: cpython: python: cpython: Quadratic algorithm in
xml.dom.minidom leads to denial of service (bsc#1254997).
* CVE-2025-13462: incorrect parsing of TarInfo header when GNU long name and
type AREGTYPE are combined (bsc#1259611).
* CVE-2025-13836: When reading an HTTP response from a server, if no read
amount is specified, the default behavior will be to use Content-Length
(bsc#1254400).
* CVE-2025-13837: When loading a plist file, the plistlib module reads data in
size specified by the file itself, meaning a malicious file can cause...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-1349=1 openSUSE-SLE-15.6-2026-1349=1
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-1349=1
* Python 3 Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-1349=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1349=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1349=1
* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586)
* python311-tk-debuginfo-3.11.15-150600.3.53.1
* python311-testsuite-3.11.15-150600.3.53.1
* python311-debugsource-3.11.15-150600.3.53.1
* python311-base-3.11.15-150600.3.53.1
* python311-curses-3.11.15-150600.3.53.1
* python311-tk-3.11.15-150600.3.53.1
* libpython3_11-1_0-3.11.15-150600.3.53.1
* python311-base-debuginfo-3.11.15-150600.3.53.1
* python311-core-debugsource-3.11.15-150600.3.53.1
* python311-testsuite-debuginfo-3.11.15-150600.3.53.1
* python311-doc-devhelp-3.11.15-150600.3.53.1
* python311-doc-3.11.15-150600.3.53.1
* python311-tools-3.11.15-150600.3.53.1
* python311-curses-debuginfo-3.11.15-150600.3.53.1
* python311-3.11.15-150600.3.53.1
* python311-debuginfo-3.11.15-150600.3.53.1
* python311-idle-3.11.15-150600.3.53.1
* python311-devel-3.11.15-150600.3.53.1
* libpython3_11-1_0-debuginfo-3.11.15-150600.3.53.1
* python311-dbm-debuginfo-3.11.15-150600.3.53.1
* python311-dbm-3.11.15-150600.3.53.1
* openSUSE Leap 15.6 (x86_64)
*...
Read the Full Advisory* bsc#1252974
* bsc#1254400
* bsc#1254401
* bsc#1254997
* bsc#1257029
* bsc#1257031
* bsc#1257042
* bsc#1257046
* bsc#1257181
* bsc#1259240
* bsc#1259611
* bsc#1259734
* bsc#1259735
* bsc#1259989
* bsc#1260026
## References:
* https://www.suse.com/security/cve/CVE-2025-11468.html
* https://www.suse.com/security/cve/CVE-2025-12084.html
* https://www.suse.com/security/cve/CVE-2025-13462.html
* https://www.suse.com/security/cve/CVE-2025-13836.html
* https://www.suse.com/security/cve/CVE-2025-13837.html
* https://www.suse.com/security/cve/CVE-2025-15282.html
* https://www.suse.com/security/cve/CVE-2025-6075.html
* https://www.suse.com/security/cve/CVE-2026-0672.html
* https://www.suse.com/security/cve/CVE-2026-0865.html
* https://www.suse.com/security/cve/CVE-2026-1299.html
* https://www.suse.com/security/cve/CVE-2026-2297.html
* https://www.suse.com/security/cve/CVE-2026-3479.html
* https://www.suse.com/security/cve/CVE-2026-3644.html
* https://www.suse.com/security/cve/CVE-2026-4224.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.